<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[#GitHub was compromised again… via a poisoned #VSCode extension.]]></title><description><![CDATA[<p><a href="https://phpc.social/tags/GitHub" rel="tag">#<span>GitHub</span></a> was compromised again… via a poisoned <a href="https://phpc.social/tags/VSCode" rel="tag">#<span>VSCode</span></a> extension.</p><p><div class="card col-md-9 col-lg-6 position-relative link-preview p-0">

<div class="card-body">
<h5 class="card-title">
<a href="https://xcancel.com/github/status/2056949168208552080">
 X Cancelled | Verifying your request
</a>
</h5>
<p class="card-text line-clamp-3"></p>
</div>
<a href="https://xcancel.com/github/status/2056949168208552080" class="card-footer text-body-secondary small d-flex gap-2 align-items-center lh-2">



<img src="https://xcancel.com/favicon.ico" alt="favicon" class="not-responsive overflow-hiddden" style="max-width: 21px; max-height: 21px;" />



<p class="d-inline-block text-truncate mb-0"> <span class="text-secondary">(xcancel.com)</span></p>
</a>
</div></p><p> <div class="card col-md-9 col-lg-6 position-relative link-preview p-0">

<div class="card-body">
<h5 class="card-title">
<a href="https://xcancel.com/github/status/2056884788179726685">
 X Cancelled | Verifying your request
</a>
</h5>
<p class="card-text line-clamp-3"></p>
</div>
<a href="https://xcancel.com/github/status/2056884788179726685" class="card-footer text-body-secondary small d-flex gap-2 align-items-center lh-2">



<img src="https://xcancel.com/favicon.ico" alt="favicon" class="not-responsive overflow-hiddden" style="max-width: 21px; max-height: 21px;" />



<p class="d-inline-block text-truncate mb-0"> <span class="text-secondary">(xcancel.com)</span></p>
</a>
</div></p>]]></description><link>https://board.circlewithadot.net/topic/49487f50-813e-4807-b5d9-2067fb0fb4df/github-was-compromised-again-via-a-poisoned-vscode-extension.</link><generator>RSS for Node</generator><lastBuildDate>Mon, 25 May 2026 12:15:17 GMT</lastBuildDate><atom:link href="https://board.circlewithadot.net/topic/49487f50-813e-4807-b5d9-2067fb0fb4df.rss" rel="self" type="application/rss+xml"/><pubDate>Wed, 20 May 2026 12:56:55 GMT</pubDate><ttl>60</ttl><item><title><![CDATA[Reply to #GitHub was compromised again… via a poisoned #VSCode extension. on Wed, 20 May 2026 14:11:43 GMT]]></title><description><![CDATA[<p><span><a href="/user/ghostwriter%40phpc.social" rel="nofollow noopener">@<span>ghostwriter</span></a></span> <br />Ah, apparently it was <a href="https://www.stepsecurity.io/blog/nx-console-vs-code-extension-compromised" rel="nofollow noopener">compromised</a></p>]]></description><link>https://board.circlewithadot.net/post/https://infosec.exchange/users/wdormann/statuses/116607307191471029</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://infosec.exchange/users/wdormann/statuses/116607307191471029</guid><dc:creator><![CDATA[wdormann@infosec.exchange]]></dc:creator><pubDate>Wed, 20 May 2026 14:11:43 GMT</pubDate></item><item><title><![CDATA[Reply to #GitHub was compromised again… via a poisoned #VSCode extension. on Wed, 20 May 2026 13:39:16 GMT]]></title><description><![CDATA[<p><span><a href="/user/ghostwriter%40phpc.social" rel="nofollow noopener">@<span>ghostwriter</span></a></span> <br />A "poisoned" VSCode extension...</p><p>Does that convey a legitimate extension that was compromised (in what way?)?</p><p>Or a VSCode extension that is inherently malicious?</p><p>I feel like there's an important difference.</p>]]></description><link>https://board.circlewithadot.net/post/https://infosec.exchange/users/wdormann/statuses/116607179587554412</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://infosec.exchange/users/wdormann/statuses/116607179587554412</guid><dc:creator><![CDATA[wdormann@infosec.exchange]]></dc:creator><pubDate>Wed, 20 May 2026 13:39:16 GMT</pubDate></item></channel></rss>